Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Radsec client Certificate can't upload

This thread has been viewed 27 times
  • 1.  Radsec client Certificate can't upload

    Posted 10 days ago

    Hello,

    I am currently configuring an Aruba 6000 switch for a Radsec connection. I'm trying to upload my certificate generated by SCEPman for client authentication, and I keep getting this error:

    Moreover, it remains in its "csr_pending" state.

    Do you have any ideas?

    Thank you in advance.



  • 2.  RE: Radsec client Certificate can't upload

    EMPLOYEE
    Posted 9 days ago

    I generally use  inbuilt device certificate of CX switches for Radsec.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: Radsec client Certificate can't upload

    Posted 9 days ago

    Hi,

    Thanks for your response, if I use inbuilt device certificate how it will be able to be authenticated for Radsec connection ?

    Because the certification authority will not recognize this certificate.




  • 4.  RE: Radsec client Certificate can't upload

    EMPLOYEE
    Posted 9 days ago

    check this short guide for "Radsec and Aruba ClearPass – Part2"

    but basically on the switch you configure it to use its device certificate for radsec and then import the CA certificate that signed ClearPass's  radsec cert. (assuming you are using ClearPass at the other end of radsec. Also note that ClearPass already has the CA certificate that signed the device cert for switches and APs, all you have to do is enable it.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 5.  RE: Radsec client Certificate can't upload

    Posted 9 days ago

    Okay, thank you, I understand why. The problem is that I'm not using Clearpass at the other end of Radsec. Is there a specific way or format to upload a certificate to the switch?




  • 6.  RE: Radsec client Certificate can't upload

    EMPLOYEE
    Posted 9 days ago

    you can refer to the PKI section of the security guide for CX6000 switches. 



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 7.  RE: Radsec client Certificate can't upload

    Posted 3 days ago

    I followed the prerequisites for the certificate to be imported in the documentation you provided, but unfortunately, I still get the same error; it does not accept the certificate at all.

    Do you have any ideas, because I admit I'm running out of them ^^




  • 8.  RE: Radsec client Certificate can't upload

    EMPLOYEE
    Posted yesterday

    It's probably something in the certificate, which is hard to pinpoint without having access to it. The switch logs may provide some additional information.

    If you follow the documentation, it's expected to work. Your Aruba partner or TAC may be able to assist you in analyzing the certifcate or checking the switch logs.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 9.  RE: Radsec client Certificate can't upload

    Posted 4 hours ago

    As per the error message, there is something wrong with the format of the private key you want to import. 

    You can try import cert via cli. It need to be in PEM format.

    Best, Gorazd 



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2024
    ------------------------------